Friday, March 23, 2012

thecheapostore.com - The face of Identify Theft?



TheCheapOStore.com - Everything is sold for 99 cents, including your identity?

Thecheapostore.com is an anomoly in a world of cheap stuff and people searching for the cheapest stuff. At the thecheapostore.com you can buy anything for 99 cents but whether anything actually gets sold is another question.

As you might probably guess, I am constantly making my friends and family aware of malicious internet "stuff". Apparently, they listen.

My wife approached me yesterday to tell me about what she considered a funny story about a website where she was trying to puchase something. The website was called thecheapostore.com. Apparently, everything is on auction and everything costs 99 cents.

There were two funny things about it she told me. The first was that when she tried to purchase, my network identity theft protection fired off an prevented her from going to the website . The second was that all auctions start at 99 cents, end in 30 minutes, but if you refresh your browser, the clock starts again.

"DING!"

So I asked her to show me the site. Here is my short analysis:

The site itself is a simple front end showing "Latest Products", and it opens rather slow, presumably because it is a DSL connection as reported by centralops.

The products are presented to you in an iframe from another website madsem.com


<iframe src="http://campaigns.madsem.com/magentoshops/index.php" width="350" height="280" frameborder="0" scrolling="no"></iframe>

Now, go to madsem.com

It says only.

"welcome Biatches :)"


So what exactly happens to your information when you click "Send". Someone has it. And he thinks your a biatch.

My suggestion is to research websites before you send their information or making a purchase.

http://www.scamadviser.com/is-thecheapostore.com-safe.html
http://www.webutation.net/go/review/thecheapostore.com#
http://answers.yahoo.com/question/index?qid=20120314153644AArQVTz

Registrant:
   Domains By Proxy, LLC
   DomainsByProxy.com
   15111 N. Hayden Rd., Ste 160, PMB 353
   Scottsdale, Arizona 85260
   United States

Registered through: GoDaddy.com, LLC (http://www.godaddy.com)

IP Address:
82.211.28.22
ACCELERATED IT SERVICES GMBH
Germany
DAWN-SERVER.DE
ip2location.com lists this as a DSL connection

Queried whois.ripe.net with "-B 82.211.28.22"...

% Information related to '82.211.28.0 - 82.211.28.255'

inetnum:         82.211.28.0 - 82.211.28.255
netname:         DE-MEDIA-IP-NETWORK-20110823
descr:           Media IP Network
country:         DE
admin-c:         HN1156-RIPE
tech-c:          HN1156-RIPE
status:          ASSIGNED PA
remarks:         ************************************************
remarks:         * ABUSE CONTACT: medianetworksg@gmail.com IN   *
remarks:         * CASE OF HACK ATTACKS,ILLEGAL ACTIVITY,       *
remarks:         * VIOLATION, SCANS, PROBES, SPAM, ETC.         *
remarks:         ************************************************
mnt-by:          ACCELERATED-MNT
changed:         nk@accelerated.de 20110823
source:          RIPE

person:          Hang Nguyen
address:         Duong 8B Pho 4 Bin An, Quan 2
address:         Saigon, Vietnam
phone:           +84 906482860
e-mail:          medianetworks@gmail.com
nic-hdl:         HN1156-RIPE
mnt-by:          ACCELERATED-MNT
changed:         lir@accelerated.de 20110623
source:          RIPE

% Information related to '82.211.0.0/18AS31400'

route:          82.211.0.0/18
descr:          IP-Routing by Accelerated IT Services GmbH
origin:         AS31400
mnt-by:         ACCELERATED-MNT
changed:        nk@accelerated.de 20080709
source:         RIPE

Traceroute

 6  TenGigE0-0-1-0.GW14.BOS4.ALTER.NET (152.179.2.97)  80.593 ms  81.399 ms  81.   276 ms
 7  0.ge-0-3-0.XL4.BOS4.ALTER.NET (152.63.17.134)  80.176 ms  86.179 ms  85.477    ms
 8  0.xe-7-0-3.XL4.IAD8.ALTER.NET (152.63.2.106)  105.865 ms  103.278 ms  112.64   8 ms
 9  0.ae4.BR1.IAD8.ALTER.NET (152.63.33.121)  104.557 ms  117.249 ms  97.695 ms
10  194.25.211.17 (194.25.211.17)  102.064 ms  111.042 ms  182.673 ms
11  f-ed6-i.F.DE.NET.DTAG.DE (62.156.131.242)  259.001 ms 194.25.6.90 (194.25.6.   90)  256.655 ms  251.036 ms
12  80.156.160.162 (80.156.160.162)  260.455 ms  242.994 ms  241.802 ms
13  fra4.xe-0-1-0.accelerated.de (84.200.230.81)  225.309 ms  224.549 ms  212.82   0 ms
14  82.211.28.22 (82.211.28.22)  228.830 ms  216.740 ms  215.035 ms

No comments:

Post a Comment